Privacy Policy
Last updated 27 July 2026
The short version
- Your screen time never leaves your phone. Oath measures which apps you use and for how long, and that record stays in local storage on your device. It is not uploaded, not backed up to our servers, and we cannot see it.
- What does leave your phone is what a Pact needs to work: your name and email from Google Sign-In, the rules you agree with your partner, and a record of when a rule was broken.
- We do not sell your data, and Oath contains no advertising or analytics trackers.
- Your partner sees less than you might expect. They are not told when you break a rule. Details in "What your partner can see".
Our contact details
Name: Immanuel Rajiv, trading as Way Studio — a sole trader based in the United Kingdom.
E-mail: waystudio.apps@gmail.com
For the purposes of UK data protection law we are the "controller" of the personal data described in this policy. This policy covers the Oath Android app (package com.waystudio.oath) and this website.
We are a sole trader and are not required to appoint a Data Protection Officer, so please send all data protection queries to the address above.
The type of personal information we collect
What stays on your phone only
The following is stored in a database on your device and is never transmitted to us or anyone else. If you uninstall Oath, it is deleted with the app.
- App usage statistics: which apps you opened, how long each was in the foreground, how many times you picked up your phone, and the category we assign each app.
- Focus sessions and schedules: the sessions you run, the apps you chose to block, and your allow-list.
- Your settings and preferences.
Oath reads this information using Android's Usage Access permission, which you grant during setup and can withdraw at any time in your phone's settings.
What is sent to our servers
Oath uses Google Firebase to let two people share a Pact across two phones. Only the data below is sent.
| Data | Why it is needed |
|---|---|
| Google account details | Your display name, email address, profile photo URL, and a Google-issued user ID. Used to sign you in and to show your partner who they are paired with. |
| Notification token | A Firebase Cloud Messaging token identifying your device, so your partner's phone can reach yours with a notification. |
| Pact and rule content | The rules you and your partner agree: the rule name, the time limits and windows, and the package names of the apps you name in a rule (for example com.instagram.android). Both partners must see the same rules, so they are stored centrally. |
| Breach records | When a rule was broken, which rule, the app that triggered it, and how it was resolved. Also any note you type when requesting a key, and any note your partner types when declining. |
| Partner linkage | Which two accounts are joined in a Pact, and the short invite code used to join. |
| Subscription status | Whether your account is in a trial or has an active subscription, verified with Google Play. We never see your card details; Google handles payment. |
The third row is worth reading twice. We never receive your usage figures, but a rule you write does name the apps it governs, and a breach record names the app that triggered it. If you would rather an app was not named on our servers, keep it out of a shared rule.
How we get your personal information and why we collect it
Most of the personal information we process is provided to us directly by you, when you sign in with Google, when you write a rule, and when you send a note to your partner. We also receive information indirectly from two sources: Google Sign-In gives us your name, email address and profile photo URL when you authorise it, and Google Play tells us whether your subscription is active.
We use that information to create and run your account, to keep your Pact in step across two phones, to let your partner grant you a key, to send the notifications described below, and to confirm you are entitled to the paid features.
The Accessibility Service
Oath cannot block an app without Android's Accessibility Service, so we ask you to turn it on. It is a powerful permission, so here is the whole of what Oath does with it.
- Oath uses the service for one purpose: to detect which app has just come to the foreground, so it can show a blocking screen when that app is covered by an active rule or focus session.
- Oath does not read, record, or transmit the contents of your screen, what you type, your messages, your passwords, or anything inside other apps.
- The foreground app name is evaluated on your device and is not sent anywhere, except where a package name forms part of a rule or a breach record as described above.
- You can turn the service off at any time in Android Settings. Blocking then stops working.
Oath also requests permission to see the list of apps installed on your device, so you can choose apps when writing a rule. That list is used on your device to draw the picker and is not uploaded.
Our lawful bases
Under the UK GDPR, the lawful bases we rely on for processing this information are:
- (a) Your consent. This covers the Usage Access permission, the Accessibility Service, and notifications. You are able to remove your consent at any time — each one can be withdrawn in your Android settings, and you can also contact us at waystudio.apps@gmail.com.
- (b) We have a contractual obligation. This covers your account details, Pact and rule content, breach records, and subscription status. Without these, the service you signed up for cannot function.
- (f) We have a legitimate interest. This covers keeping the service secure and preventing abuse, including Google Play Integrity checks that confirm requests come from a genuine copy of the app.
What your partner can see
A Pact shows your partner less than most people expect. They can see:
- Your display name and profile photo.
- The rules you both agreed, and any change either of you proposes.
- A shared history of breaches on the Pact, and whether each was resolved.
- Any note you write when you ask them for a key.
Your partner is not sent a notification when you break a rule. Breaches are quiet by default. They are notified only when you ask them for a key, when you use a hammer to release yourself, when they decline a request, and when the Pact is paused, revived, or dissolved.
Your partner never sees your screen time figures, your app usage, your focus sessions, or any app you have not named in a shared rule.
Who we share your information with
We use a small number of processors, and we do not sell data to anyone.
- Google Firebase (Google Ireland Limited), for authentication, database, notifications, and app integrity checks. Our database is hosted in Google's
eur3European multi-region, which stores data in Belgium and the Netherlands. Our server functions run in Belgium. - Google Play Billing: subscriptions and payment. Google is the seller and handles your payment details directly. See Google's own privacy policy for how they process them.
- Formspree: used only on this website, to receive the early-access sign-up form. If you enter your email on the form, it reaches us through Formspree.
- Google Fonts: this website loads its typefaces from Google's font service, which means Google receives your IP address when a page loads. The app does not do this.
We may also disclose data where the law requires it, or to protect our rights or someone's safety.
Cookies. This website sets no cookies and contains no analytics or advertising trackers. Your visit is not tracked. The Oath app sets no cookies either.
How we store your personal information
Your information is securely stored with Google Firebase, in the eur3 European multi-region (Belgium and the Netherlands). Access to our database is governed by server-side security rules that restrict every record to the people party to it, and sensitive operations run as server functions rather than being trusted to the app. Subscription entitlements are verified on our server, not on your phone. Requests are checked with Google Play Integrity to confirm they come from a genuine, unmodified copy of Oath.
Our database region is in the EEA. Google, as our processor, may transfer or access data outside the UK and EEA in the course of running its infrastructure and support. Where that happens, transfers are covered by the UK International Data Transfer Addendum or Standard Contractual Clauses.
We keep your information for the following periods, after which it is deleted from our database:
- Account details: until you delete your account.
- Pact, rule, and breach records: for as long as the Pact exists. When a Pact is dissolved it is archived to your history and your partner's history, because it is a shared record that belongs to both of you. It is removed when either of you deletes your account, apart from one thing: your partner keeps a short marker saying the Pact ended and that you ended it, and that marker includes your display name. Their phone needs it to close the Pact and to lift any block it was still holding. It contains nothing else about you.
- Invite codes: deleted once the invite is accepted or the Pact ends.
- Notification tokens: replaced when Android reissues them, and removed when you delete your account.
- On-device data: kept until you clear the app's storage or uninstall it. This one is in your hands, not ours.
No service can promise perfect security, and we do not. If a breach occurs that puts your rights at risk, we will tell you and the ICO as the law requires.
Automated decision-making
We do not make automated decisions about you that produce legal effects or similarly significant effects, and we do not profile you.
Oath does apply your own rules automatically — when an app you named goes past a limit you agreed, that app is sealed without anyone reviewing it first. That is the function you asked for. It affects only that app, only on your own phone, and it is not used to judge you, score you, or decide anything about you beyond the rule you wrote.
Your data protection rights
Under data protection law, you have rights including:
- Your right of access — You have the right to ask us for copies of your personal information.
- Your right to rectification — You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Your right to erasure — You have the right to ask us to erase your personal information in certain circumstances.
- Your right to restriction of processing — You have the right to ask us to restrict the processing of your personal information in certain circumstances.
- Your right to object to processing — You have the right to object to the processing of your personal information in certain circumstances.
- Your right to data portability — You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
- Your right to withdraw consent — Where we rely on your consent, you have the right to withdraw it at any time.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at waystudio.apps@gmail.com if you wish to make a request.
To delete your account and the data attached to it, see Deleting your account.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at waystudio.apps@gmail.com. We would rather you told us first so we can put it right.
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO's address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
Children
Oath is not designed for children and is not directed at them. You must be at least 18 to use it. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell you in the app before it takes effect.